Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

Kubernetes 1.37 - New security features

Blog post from Sysdig

Post Details
Company
Date Published
Author
Victor Jimenez Cerrada
Word Count
2,233
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

Kubernetes 1.37 introduces 67 enhancements, including 19 changes with security implications across storage, networking, authentication, workload isolation, and disaster recovery. Notable potentially disruptive updates include stable SELinux mount labeling, which accelerates volume mounting but can affect volumes shared by Pods with differing labels, warnings for clusters still using iptables ahead of nftables becoming kube-proxy’s default in 1.40, and a fix preventing static Pods from referencing Secrets or ConfigMaps. New alpha capabilities include TLS support for gRPC probes, restrictive mount options such as noexec and nosuid, configurable ownership for ConfigMap and Secret-based volumes, Pod-level checkpoint and restore, snapshot topology controls, and API server authentication to admission webhooks. Features enabled by default include rootless kubelet operation in user namespaces, PVC unused-time reporting, and manifest-based admission configuration, while stable improvements include ClusterTrustBundles, workload certificates, custom Pod FQDNs, and KYAML output. The release also exposes additional operational data through APIs, prompting administrators to review access controls because such information may aid infrastructure reconnaissance.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 40 3,490 385 112 +26%
Secrets Management 3 2,244 480 132 -13%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.